CWE-285

High likelihood

Improper Authorization

Parent: CWE-284 - Improper Access Control

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

1,461 vulnerabilities with CWE-285
CVE-2026-33398 HIGH
Authenticated users can read hidden forum posts through `/forum/get_quotes`
CVE-2026-41115 MEDIUM
Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
CVSS 4.3
CVE-2026-10294 MEDIUM
PackageKit <= 1.3.5 - Improper Authorization via Frontend-Socket Argument
CVSS 4.3
CVE-2026-10285 MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Improper Authorization in KanbanScrumHelper Ticket Handler
CVSS 5.4
CVE-2026-10284 MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Incorrect Privilege Assignment in Livewire Handler
CVSS 5.4
CVE-2026-45275 MEDIUM
Nextcloud Approval < 2.7.2 - Privilege Escalation via Forced File Sharing
CVSS 6.5
CVE-2026-10282 MEDIUM
Bottelet DaybydayCRM <= 2.2.1 - Incorrect Privilege Assignment in DocumentsController
CVSS 4.3
CVE-2026-0072 HIGH
Android XR 14 InputMethodManagerService - Missing Permission Check Privilege Escalation
CVSS 7.8
CVE-2026-10272 MEDIUM
a4m4 Student-Management-System deleteform.php improper authorization
CVSS 6.5
CVE-2026-10269 MEDIUM
decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization
CVSS 6.3
CVE-2026-46605 MEDIUM
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
CVSS 4.3
CVE-2026-40963 LOW
Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
CVSS 3.1
CVE-2026-10236 HIGH
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
CVSS 7.3
CVE-2026-10218 MEDIUM
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
CVSS 5.4
CVE-2026-10215 MEDIUM
Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
CVSS 4.3
CVE-2026-10212 MEDIUM
AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization
CVSS 6.3
CVE-2026-10211 MEDIUM
AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVSS 6.3
CVE-2026-10154 MEDIUM
Dolibarr ERP CRM messaging.php authorization
CVSS 4.3
CVE-2026-48810 MEDIUM
FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check
CVSS 4.3
CVE-2026-47744 CRITICAL
Shopper: Authorization bypass and RBAC privilege escalation in team settings
CVSS 9.9
CVE-2026-47740 HIGH
Shopper: Authorization bypass in multiple Livewire admin components
CVSS 8.1
CVE-2026-10070 MEDIUM
macrozheng mall Super Admin Password update improper authorization
CVSS 4.7
CVE-2026-45620 MEDIUM
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration
CVSS 5.3
CVE-2026-47713 LOW
AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration
CVSS 2.0
CVE-2026-45297 MEDIUM
Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch
Details
Vulnerabilities 1,461
Exploit Likelihood High